This Data Processing Agreement ("DPA") forms part of the Master Subscription Agreement ("Agreement") between Signitiva LLC, a Texas limited liability company, Houston, Texas, USA, provider of the Moderandi platform ("Moderandi" or "Processor") and the customer identified in the applicable Order Form ("Customer" or "Controller"), and applies to the extent Moderandi processes Personal Data on Customer's behalf in providing the Services.
1. Definitions
- "Data Protection Laws" — all laws applicable to the processing of Personal Data under the Agreement, which may include the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, Brazil's Lei Geral de Proteção de Dados, Law No. 13.709/2018 ("LGPD"), the California Consumer Privacy Act as amended by the CPRA ("CCPA"), other applicable US state privacy laws, and other applicable national data-protection laws (including those of Latin American jurisdictions where Customer operates).
- "Personal Data" — any information relating to an identified or identifiable natural person contained in Customer Data.
- "Processing," "Controller," "Processor," "Data Subject," "Personal Data Breach" — as defined in the GDPR; for CCPA purposes, "Processor" includes "Service Provider," "Personal Data" includes "Personal Information," and "Data Subject" includes "Consumer."
- "Subprocessor" — a third party engaged by Moderandi to process Personal Data on Customer's behalf.
- "SCCs" — the European Commission's Standard Contractual Clauses for the transfer of personal data to third countries (Decision 2021/914), as applicable.
2. Roles and Scope
2.1 Customer is the Controller (or, where Customer acts for its own client, a Processor acting on documented instructions of that client) and Moderandi is the Processor of Personal Data processed through the Services.
2.2 The subject matter, duration, nature and purpose of processing, categories of Personal Data, and categories of Data Subjects are described in Annex I.
2.3 This DPA applies for the term of the Agreement and for as long as Moderandi processes Personal Data on Customer's behalf. In case of conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails; the limitations of liability in the Agreement apply to this DPA.
3. Customer Instructions
3.1 Moderandi will process Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required otherwise by law to which Moderandi is subject — in which case Moderandi will inform Customer of that legal requirement before processing, unless the law prohibits it.
3.2 The Agreement, this DPA, and Customer's configuration and use of the Services (including workflows, integrations, and add-ons the Customer enables) constitute Customer's complete documented instructions. Additional instructions require written agreement of both parties.
3.3 Moderandi will inform Customer if, in its opinion, an instruction infringes Data Protection Laws; Moderandi is not obligated to perform a legal review of Customer's instructions.
3.4 Customer is responsible for the lawfulness of the Personal Data it submits, including any notices to and consents from Data Subjects (including Customer's own end customers whose data enters the Services through the Customer Portal or otherwise).
4. Confidentiality of Processing
Moderandi ensures that persons authorized to process Personal Data are bound by confidentiality obligations (contractual or statutory) and access Personal Data only as needed to provide the Services.
5. Security
5.1 Moderandi implements and maintains the technical and organizational measures described in Annex II ("TOMs"), designed to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.
5.2 Moderandi may update the TOMs from time to time, provided updates do not materially reduce the overall level of protection during a subscription term.
6. Subprocessors
6.1 General authorization. Customer provides general written authorization for Moderandi to engage Subprocessors. The current list is set out in Annex III and maintained at moderandi.com/legal/subprocessors.
6.2 Notice of changes. Moderandi will give Customer at least 30 days' prior notice of the addition or replacement of a Subprocessor (via the subprocessor page and/or notice to the billing contact — Customer may subscribe to change notifications at the subprocessor page).
6.3 Objection. If Customer reasonably objects on data-protection grounds within the notice period, the parties will discuss in good faith a resolution (e.g., a configuration avoiding the Subprocessor). If none is reasonably available, Customer may terminate the affected subscription with a pro-rata refund of prepaid fees for the unused remainder of the term, as its sole remedy.
6.4 Flow-down. Moderandi will impose on each Subprocessor data-protection obligations materially no less protective than those in this DPA, and remains liable for its Subprocessors' performance.
7. Data Subject Requests
Taking into account the nature of the processing, Moderandi will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection). In practice, the Services provide Customer-facing capabilities to access, correct, export, and delete records. If a Data Subject contacts Moderandi directly regarding Personal Data processed for Customer, Moderandi will (to the extent legally permitted) redirect the Data Subject to Customer and will not respond substantively without Customer's authorization, unless legally required.
8. Personal Data Breach
Moderandi will notify Customer without undue delay, and in any event within 5 business days, after becoming aware of a Personal Data Breach affecting Personal Data processed on Customer's behalf. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate volumes of affected data and Data Subjects, likely consequences, and measures taken or proposed. Moderandi will provide reasonable ongoing cooperation and information to support Customer's own notification obligations. Moderandi's notification is not an acknowledgment of fault or liability.
9. Assistance with DPIAs and Consultations
Taking into account the nature of processing and information available to it, Moderandi will provide reasonable assistance with Customer's data protection impact assessments and prior consultations with supervisory authorities, where required by Data Protection Laws and related to the Services.
10. Deletion and Return of Personal Data
Upon expiration or termination of the subscription, Customer may export Customer Data (including Personal Data) during the Export Window defined in the Billing Terms (30 days). After the Export Window, Moderandi will delete Personal Data processed on Customer's behalf within the deletion period defined in the Billing Terms (90 days after the end date), except where retention is required by law, and excluding backups that are deleted or overwritten on their standard expiry schedule and remain protected by this DPA until deletion.
11. Audits and Certifications
11.1 Moderandi will make available information reasonably necessary to demonstrate compliance with this DPA, including responses to reasonable written security questionnaires (no more than once annually, absent a Personal Data Breach or regulator requirement) and copies of third-party audit reports or certifications as and when Moderandi obtains them; the hosting layer is covered by Google Cloud Platform's independent certifications and audit reports.
11.2 Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied by the above, Customer (or an independent auditor not a competitor of Moderandi) may audit Moderandi's compliance with this DPA, subject to: 30 days' notice, at most once per 12-month period, during business hours, without disrupting operations, under confidentiality obligations, and at Customer's expense. On-premise access to multi-tenant infrastructure may be limited to protect other tenants; audits of the hosting layer are satisfied by Google Cloud's audit reports.
12. International Transfers
12.1 Personal Data is hosted on Google Cloud Platform in the United States (US East region) (MSA §7.2).
12.2 Where Customer is subject to the GDPR or UK GDPR and its use of the Services involves a transfer of Personal Data to Moderandi in the United States, the parties agree that the SCCs (Module Two: Controller-to-Processor) are automatically incorporated into this DPA, with Moderandi as data importer and Customer as data exporter, completed as follows: Annexes I and II of this DPA serve as Annexes I and II of the SCCs; the optional docking clause applies; the supervisory authority and governing law of the SCCs are those of the EU member state where Customer is established (or Ireland, where none applies); for UK transfers, the UK International Data Transfer Addendum applies with this DPA supplying the appendix information.
12.3 Where Customer is subject to the LGPD and its use of the Services involves an international transfer of Personal Data to Moderandi in the United States, the parties agree that the standard contractual clauses approved by the Brazilian data protection authority (ANPD) are incorporated into this DPA upon Customer's written request, completed with the information in Annexes I and II. For other jurisdictions whose Data Protection Laws require a transfer mechanism, the parties will cooperate in good faith to put in place the required safeguards, and the protections of this DPA (including Annex II) apply to all Personal Data regardless of Customer's jurisdiction.
12.4 Moderandi will notify Customer if it can no longer comply with an applicable transfer mechanism and will cooperate on supplementary measures or suspension of the affected transfer.
13. US State Privacy Laws (CCPA/CPRA and similar)
To the extent CCPA or similar US state privacy laws apply, Moderandi acts as a Service Provider/Processor and: (a) will not sell or share Personal Data; (b) will not retain, use, or disclose Personal Data for any purpose other than providing the Services under the Agreement, or as otherwise permitted by those laws (including security, deduplication, and internal service improvement to the extent permitted); (c) will not combine Personal Data with data from other sources except as permitted for Service Providers; (d) will notify Customer if it determines it can no longer meet these obligations, in which case Customer may take reasonable steps to stop and remediate unauthorized use; and (e) certifies that it understands and will comply with these restrictions.
14. General
This DPA terminates automatically with the Agreement (surviving as long as Moderandi holds Personal Data). It may be updated by Moderandi at renewal in the manner set out for the Billing Terms, or earlier where required by Data Protection Laws, provided updates do not materially reduce protections. Signatures on the Agreement or an Order Form referencing this DPA constitute execution of this DPA, including the SCCs where applicable.
15. Annex I — Details of Processing
A. List of parties. Data exporter/Controller: Customer (contact: billing/admin contact in the Order Form). Data importer/Processor: Signitiva LLC (Moderandi), Houston, Texas, USA (contact: privacy@moderandi.com).
B. Subject matter and duration. Provision of the Moderandi field-operations SaaS platform for the subscription term, plus the export and deletion periods in the Billing Terms.
C. Nature and purpose. Hosting, storage, transmission, display, backup, and processing of Customer Data as needed to provide the subscribed modules (Admin, CRM, Finance, Sales, Projects, Agent App, and subscribed add-ons such as Customer Portal and AI Analytics), including AI-assisted features where subscribed (processing of Customer Data with AI models solely to deliver outputs to Customer; no training of generalized models).
D. Categories of Data Subjects. Customer's Users (employees, contractors, field agents); Customer's customers and prospects (CRM contacts, Customer Portal users); Customer's suppliers and business contacts; other individuals whose data Customer submits.
E. Categories of Personal Data. Identification and contact data (names, emails, phone numbers, addresses); professional data (job titles, employer); commercial data (orders, invoices, payment status, delivery details); location data of field agents to the extent enabled by Customer; communications and notes entered by Users; credentials and usage logs. Special categories: the Services are not designed for special-category/sensitive data (health, biometric, etc.); Customer agrees not to submit it unless the parties agree otherwise in writing with appropriate safeguards.
F. Frequency. Continuous, for the duration of the subscription.
16. Annex II — Technical and Organizational Measures (TOMs)
- Tenant isolation: logical multi-tenant isolation enforced at the database layer via row-level security policies scoped to the customer tenant; every runtime query executes within the tenant context.
- Access control: role-based access control within the Services; least-privilege access for Moderandi personnel; administrative access restricted, logged, and reviewed; unique credentials and multi-factor authentication required for personnel access to production systems.
- Encryption: encryption in transit (TLS); encryption at rest provided by Google Cloud Platform managed encryption.
- Audit logging: append-only audit trails of security-relevant actions within the Services, including actions by system/synthetic actors.
- Availability and resilience: hosted on Google Cloud Platform (US East); backups on a defined schedule with retention per Moderandi's documented backup policy; recovery objectives per Moderandi's documented backup and recovery procedures.
- Secure development: code review, dependency management, environment separation (development/staging/production); production Personal Data is not used in non-production environments.
- Personnel: confidentiality obligations; periodic security awareness training.
- Incident response: documented incident-response process with defined roles, triage, and customer notification per Section 8.
- Subprocessor management: contractual flow-down of data-protection obligations; periodic review of Subprocessor safeguards.
17. Annex III — Subprocessors
| Subprocessor | Purpose | Location of processing |
|---|---|---|
| Google Cloud Platform (Google LLC) | Cloud hosting, storage, and infrastructure | United States (US East) |
| Anthropic, PBC | AI-assisted features (AI Analytics and AI-powered capabilities), where subscribed | United States |
| Resend, Inc. | Transactional email and notification delivery | United States |
| Stripe, Inc. | Payment processing and billing operations | United States |
This list is mirrored at moderandi.com/legal/subprocessors, which is the authoritative current list; changes follow the notice process in Section 6.
